북한 해킹 단체 APT 37((리퍼,Reaper)에서 만든 RokRAT 악성코드-250615_양곡판매소 운영 현황.hwp(2025,06,18)
2025-08-11 • Sakai • RokRAT malware created by North Korean hacking group APT37/Reaper: grain sales office operations status HWP •
A Korean malware analysis attributes a malicious HWP document named “250615_Grain Sales Office Operations Status.hwp” to APT37/Reaper and describes it as RokRAT-themed activity. The lure content concerns grain sales and distribution in Pyongyang, indicating likely targeting of people working on North Korea-related issues or research. The document embeds a Proton Drive hyperlink and OLE objects that drop ShellRunas.exe and credui.dll into the TEMP directory when the relevant page is accessed. Infection depends on the user approving the ShellRunas.exe execution prompt, and the write-up also records a Dropbox-hosted Father.jpg URL that could not be further analyzed because the files were no longer downloadable.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 47c1cfc2380c3fa6c8283160707544fb | 2025-08-11 | 2025-08-11 |
| HASH | f20674ffc0267222555a0a23b580ee0… | 2025-08-11 | 2025-08-11 |
| HASH | 71620bd3d6462e901324f08e97bebd0… | 2025-08-11 | 2025-08-11 |
| URL | https://drive.proton.me/urls/DM… | 2025-08-11 | 2025-08-11 |
| URL | https://drive.proton.me/urls/DM… | 2025-08-11 | 2025-08-11 |
| URL | https://dl.dropboxusercontent.c… | 2025-08-11 | 2025-08-11 |
| IPv4 | 217.60.37.55 | 2025-08-08 | 2025-08-11 |